news.volyx.in

Chrome extensions spying on users' browsing data (qcontinuum.substack.com)

474 points by qcontinuum1 · 160 days ago · 205 comments on HN

Article summary

A study found 287 Chrome extensions that exfiltrate browsing history, affecting approximately 37.4 million users. These extensions are developed by various actors, including Similarweb, Curly Doggo, and Offidocs. The study used an automated scanning pipeline to detect the leaking extensions. The leaked data can be used for targeted advertising, corporate espionage, and credential harvesting.

Main themes

  • Browser extension security
  • Data exfiltration
  • Privacy concerns
  • Extension development
  • Malicious actors

What commenters say

  • Browser extensions have looser security than expected, allowing them to access sensitive information like password fields.
  • Implementing stricter security measures for extensions could break backwards compatibility with existing websites and sign-in UIs.
  • Some argue that essential extensions like uBlock Origin should be built into browsers to ensure security and trustworthiness.
  • Others believe that the browser extension system is broken and that users should install as few extensions as possible to minimize risk.
  • There is a need for better review and management of extensions, particularly in enterprise settings.
  • Open-source extensions can provide a higher level of transparency and trust, but there is still a risk of discrepancies between the open-source code and the installed extension.
  • The risk of malware and data exfiltration can be mitigated by loading extensions in developer mode or using open-source extensions that can be audited.
  • Ultimately, trust in software and extensions is relative and subjective, and users must weigh the benefits against the potential risks.